Role-specific competence
Product owners need capability boundaries and value measurement; developers need lifecycle, schemas and testing; security teams need authorization and threat models; operations teams need observability, change and incident procedures. One generic MCP presentation cannot create these different competencies.
A shared vocabulary must distinguish host, client, server, tool, resource, prompt, agent and downstream API. Confusing these roles produces incorrect ownership and security decisions.
Evidence of learning
Competence is demonstrated through reviewed tool contracts, data-flow diagrams, threat scenarios and test cases, not attendance. Exercises should use travel cases such as repricing, booking modification or disruption handling, where stale data and side effects are visible.
A mature learning path finishes with decisions teams can defend: which capability to build, which data not to expose, where authorization is enforced and how a failed transaction is recovered.
